Bounded Delegation

A governance framework for delegated judgement

Never delegate judgement without deciding its limits first.

1. Purpose

Technology continues to absorb the performance of work. The enduring organizational challenge is no longer whether work can be automated, but which judgement should be delegated, within what boundaries, and under whose accountability.

Bounded Delegation is a governance framework for managing delegated judgement.

It is:

  • a governance framework;
  • technology independent;
  • applicable to both human and automated decision-making;
  • complementary to regulatory and compliance frameworks.

It is not: 

  • a theory of organizations;
  • a maturity model;
  • a certification framework;
  • a replacement for regulatory obligations.  

The framework rests on a single principle: Capability does not imply delegation.

A system becoming capable of exercising judgement does not mean an organization should delegate that judgement.

Everything else in the framework is a consequence of this principle:

  • Delegation requires explicit boundaries.
  • Delegation is continuous, not permanent.
  • Accountability cannot be delegated to technology.

Human in the Loop represents retained authority, not manual verification.

2. Core concepts

Judgement

Judgement is the selection between multiple acceptable actions where evidence and deterministic rules no longer uniquely determine the outcome.

A practical test: Judgement exists whenever two competent people could reasonably reach different conclusions from the same evidence and rules.

Delegated judgement

Judgement consciously authorised for another actor to exercise within defined boundaries.

The actor may be a person, a team, a software system, an AI system or an external organization. 

Delegation boundary

The explicit limit of delegated judgement.

It defines:

  • what the actor may recommend;
  • what it may decide;
  • what it may execute;
  • what must escalate;
  • what remains outside its authority.

 It also defines when the delegation must be re-authorized. A boundary that exists only on paper is not explicit. It must be expressed where the actor operates.

Sub-delegation

Delegation can be nested. An authorized actor may delegate further, to people, to systems or to agents.

Two rules apply:

  1. A sub-delegation cannot exceed the original boundary.
  2. Accountability does not transfer with it. The actor that received the delegation remains answerable for everything it delegates onward.

The second rule is older than the technology that now makes it urgent: signing authority has never been transferable onward without its own authorization. 

Bounded Delegation: the goal state

Judgement is in Bounded Delegation when:

  • its purpose is defined;
  • its boundary is explicit;
  • its accountability is assigned;
  • its review is scheduled. 

The framework is named after the state it exists to create.  

The goal state is not new. Signature authority is a well-known implementation: judgement delegated to a named person, bounded by amount and scope, exercised alone or jointly, accountable by law, and publicly registered in the commercial register. Organizations have governed delegated authority this way for centuries.

The framework extends the same discipline to actors the commercial register does not see. 

Shadow judgement

Judgement exercised without a conscious organizational decision to delegate it.

The actor may be a system or a person. In either case, the organization has delegated authority by accident. 

Accountability

Responsibility for the consequences of delegated judgement.

Technology may support accountability but cannot own accountability.

3. Why judgement is different

The framework distinguishes four types of enterprise work. The first two automate naturally. The third requires a decision. The fourth stays.

Evidence

Question

What are the facts? 

Purpose

Establish reliable evidence. 

Automation objective

Maximum automation. 

Examples

  • OCR
  • document extraction
  • sensor acquisition 

Evidence itself contains an important seam: extraction establishes what exists, interpretation establishes what it means.

Interpretation is judgement wearing Evidence's clothes. 

Rules

Question

Given the evidence, what follows? 

Purpose

Apply deterministic logic. 

Automation objective

Maximum automation. 

Examples

  • tax calculation
  • accounting postings
  • workflow routing 

Rules contain the same seam. Routine application is deterministic. Boundary cases require judgement. 

Judgement

Question

What should be done? 

Purpose

Reach an appropriate decision under uncertainty.

Automation objective

Appropriate delegation, not maximum automation.

Questions include:

  • Should this judgement be delegated?
  • To whom?
  • Within what boundary? 
  • Under whose accountability?

 
Accountability

Question

Who owns the consequences? 

Purpose

Maintain responsibility for organizational outcomes. 

Automation objective

None. Technology supports accountability through audit trails, decision logs, versioned policies or performance history. Technology cannot become accountable.

4. One goal state, two failure modes

Bounded Delegation is the goal state. 

  • Shadow judgement means the organization never entered it.
  • Delegation Drift means the organization left it without noticing. 

The two failure modes look similar in their consequences but they differ in their cause, and they require different remedies. 

Shadow judgement

Delegation that was never decided.

Employees and teams can now build useful applications without involving central IT. Sometimes those applications do more than process information and begin to shape decisions nobody agreed to hand over.

The same failure occurs without any technology at all.

Examples include:

  • applications built outside central IT that recommend actions, rank candidates, prioritize work or flag anomalies;
  • AI assistants quietly becoming de facto decision makers;
  • purchased tools with embedded AI whose recommendations enter decisions unnoticed;
  • a consultant or junior employee gradually becoming the de facto decision maker. 

No boundary was set, because no delegation decision was ever made.

Shadow judgement is found through discovery: applying the Delegation Audit to systems and roles nobody registered. 

Deegation Drift

Delegation that was decided but has since diverged.

Delegation Drift is a divergence between authorized authority and effective authority.

Delegation boundaries are not static: models change, people change, processes change, regulations change, organizations change.

Without explicit governance, the effective authority exercised by a system gradually diverges from the authority originally authorized.

Examples include:

  • users relying on AI recommendations beyond their intended scope;
  • model or vendor updates changing behaviour;
  • prompt engineering expanding effective authority;
  • decision support gradually being treated as decision making. 

Delegation Drift is found through review: the recurring review step of the governance cycle. Both failure modes are governance failures before they are technical failures. 

The framework in one view

5. Continuous delegation

Delegation is not an approval. It is a governance cycle:

  • Define purpose.
  • Identify the judgement involved.
  • Decide what may be delegated.
  • Define explicit boundaries.
  • Assign accountability.
  • Monitor performance.
  • Review delegation.
  • Adjust boundaries.
  • Repeat. 

The cycle works best attached to rhythms the organization already has: release cycles, vendor reviews, periodic business reviews. A review step that requires its own bureaucracy will be bypassed.

Human in the Loop belongs here. It represents the visible edge of delegated authority and is not merely an approval button.  

Human involvement constitutes retained authority only when the human has the competence, time, information and authority to challenge, override or halt the outcome. 

A human who approves every recommendation is not exercising retained authority.

Override rates are the observable signal. When they collapse, one of two things is true: the task has revealed itself as rules rather than judgement, or retained authority has decayed into passive approval.

The first calls for redrawing the boundary deliberately. The second is Delegation Drift. Either way, the boundary is due for review. 

6. Organizational risk

The framework distinguishes two independent forms of risk.

Regulatory risk

Defined externally.

Examples:

  • EU AI Act
  • Industry regulation 

Organizations cannot change regulatory classification. 

Organizational risk

Defined internally.

Organizational risk is the mismatch between the judgement actually exercised and the judgement explicitly authorized.

The mismatch arises through:

  • judgement delegated without a decision (shadow judgement);
  • unclear delegation;
  • poorly governed delegation;
  • delegation drift. 

Unlike regulatory risk, organizational risk can be reduced through governance. 

The two risks vary independently

A recruitment AI is classified as high risk under the EU AI Act, regardless of how well it is governed. Its organizational risk can nonetheless be low: purpose defined, role documented, boundaries explicit, accountability assigned, performance monitored.

A recommendation engine outside any regulated domain carries low regulatory risk. Its organizational risk is high if it quietly drives strategic decisions nobody agreed to delegate.

Compliance addresses the first risk but only governance of delegation addresses the second. 

7. The Delegation Audit

The Delegation Audit operationalizes the framework. E

very system capable of influencing organizational decisions should be answerable through seven questions. 

1.  What judgement is the system exercising, including judgement hidden inside evidence or rules? 2.  Why is that judgement delegated? 3.  Is the boundary explicit? 4.  Is it decision support or decision making? 5.  Who remains accountable? 6.  How is delegation monitored and periodically reviewed? 7.  What changes require re-authorization of the delegation?

A system that cannot answer these questions is likely exercising judgement that has been delegated accidentally.

The Audit applies equally to enterprise AI platforms, internally developed applications, AI agents, purchased tools, small end-user applications and human roles. Applied to registered systems, it detects Delegation Drift. Applied to unregistered systems, it discovers shadow judgement. 

8. Relationship to compliance

External governance frameworks answer questions such as:

  • What does regulation require?
  • Which controls must exist?

Bounded Delegation answers a different question: What judgement has this organization consciously decided to delegate?   

Some frameworks ask parts of this question. None can answer it. Only the organization itself can.

Compliance and governance answer different questions. Both are necessary, and neither replaces the other.


Bounded Delegation, version 1.0 , August 2026. 
Changes to the framework are versioned. The framework practices the review cycle it describes.

Search